Skip to main content
CybersecurityVulnerability Management

Microsoft Patch Tuesday Disrupts 400 Vulnerabilities, Zero-Day Exploits

IT professional standing in data center with server rack and open laptop.

“Confidentiality, integrity, and availability impacts are all rated high,” explained Action1 co-founder, Mike Walters.

Mike Walters' warning and the immediate lift for sysadmins

Microsoft's August Patch Tuesday, released on August 11, delivered 400 CVEs — a heavy load for administrators, and the second consecutive month of elevated volume. The company issued one actively exploited zero-day among them and two publicly disclosed, not-yet-exploited zero days. The combination of volume and severity, Walters' comment implies, raises triage stakes: fixes that affect confidentiality, integrity and availability should move toward the front of patch queues.

Active zero-day: CVE-2026-68820 in the Windows Ancillary Function Driver for WinSock

The single actively exploited zero day this month is CVE-2026-68820, a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock. Microsoft described the flaw as exploitable by a locally authenticated attacker with low privileges who could run a specially crafted application and trigger a race condition to gain system privileges and “extensive control over a targeted Windows system.” Action1's assessment underscores the practical risk: “Exploitation has been detected in the wild, so deployment should be prioritized even though the vulnerability is rated important rather than critical,” Walters said.

Two publicly disclosed zero days: CVE-2026-62832 and CVE-2026-72971

August also included two publicly disclosed zero days that Microsoft did not report as exploited in the wild. The first, CVE-2026-62832, is an Elevation of Privilege vulnerability in the Windows User Profile Service. Action1 director of vulnerability research Jack Bicer explained the mechanics: “An attacker with credentials for another local account could run a specially crafted application to load another user's registry hive, potentially accessing or modifying that user's data and gaining administrator privileges. No user interaction is required.” Action1 recommended prioritizing deployment because successful exploitation could provide administrator privileges and compromise sensitive user data.

The second publicly disclosed zero day, CVE-2026-72971, affects the Windows Container Isolation FS Filter Driver (unionfs.sys) and is described by Microsoft as a tampering vulnerability tied to “improper link resolution before file access.” Microsoft warned that an authenticated attacker who has credentials for another local account could run a specially crafted application to load another user's registry hive; successful exploitation could allow access to or modification of another user's data and the gain of administrator privileges. As with the User Profile Service flaw, user interaction is not required.

Scale and severity: 400 CVEs, RCEs and EoPs dominate

Microsoft's August bulletin was not a one-off in volume: July's Patch Tuesday set a record at 570 CVEs. While August's 400 CVEs did not eclipse that mark, the composition matters. The majority of fixes this month addressed elevation of privilege (EoP) and remote code execution (RCE) flaws. Of particular note, 37 RCE bugs were rated “critical,” contributing to a total of 42 critical vulnerabilities in the release. For organizations without automated, risk-based patching programs, Microsoft’s output presents a processing challenge: handling hundreds of patches while identifying and prioritizing the most dangerous flaws.

What this means for technologists, affected enterprises, and end users

  • Technologists and security teams: The combination of an actively exploited zero day and two publicly disclosed EoP flaws means patching and risk-based prioritization should be front-of-mind. The source explicitly notes that exploitation has been detected in the wild for CVE-2026-68820 and that deployment should be prioritized despite an “important” rating; similarly, Action1 urged prioritization for CVE-2026-62832 because successful exploitation could provide administrator privileges.
  • Affected enterprises and procurement leaders: Microsoft’s release underscores the operational benefit of automated, risk-based patching programs. The source states the August load “will be a challenge to process for organizations without automated, risk-based patching programs,” signaling that organizations lacking such processes will face increased triage and deployment burden.
  • End users and the general public: Two publicly disclosed zero days and one actively exploited zero day are described as requiring no user interaction in successful exploitation scenarios; this means account credential protection and rapid system updates matter for limiting exposure to privilege-escalation paths that could disclose or modify user data.

Microsoft's August bulletin — with an actively exploited use-after-free in WinSock, two publicly disclosed elevation-of-privilege flaws that can load other users' registry hives, and dozens of critical RCEs — leaves clear operational instructions in the text: prioritize deployment where exploitation is observed or where successful exploitation could yield administrator privileges, and recognize the processing burden of hundreds of fixes without automated, risk-based systems. The immediate question the facts leave is procedural: which organizations will accelerate risk-based automation to absorb this cadence, and which will continue to be strained by manual triage?

https://www.infosecurity-magazine.com/news/microsoft-fixes-400-flaws-august/